<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elblogg &#187; undring</title>
	<atom:link href="http://blog.elzapp.com/tag/undring/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.elzapp.com</link>
	<description>blogge v1 (norr bloðga, av *blod) skjære, stikke fisk slik at blodet renner ut, jf *bløgge</description>
	<lastBuildDate>Wed, 01 Sep 2010 08:41:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Mirror</title>
		<link>http://blog.elzapp.com/2008/04/04/mirror.html</link>
		<comments>http://blog.elzapp.com/2008/04/04/mirror.html#comments</comments>
		<pubDate>Fri, 04 Apr 2008 06:52:46 +0000</pubDate>
		<dc:creator>elzapp</dc:creator>
				<category><![CDATA[english]]></category>
		<category><![CDATA[misc]]></category>
		<category><![CDATA[undring]]></category>

		<guid isPermaLink="false">http://blog.elzapp.com/?p=315</guid>
		<description><![CDATA[Yesterday evening when we where going home after visiting a friend and collegue of mine, we passed by some rubbish bins outside an apartment complex. On the top of these bins there were lying a huge mirror. About 2meters 20cm by 40cm or something. There was, as far as what we could see nothing wrong [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday evening when we where going home after visiting a friend and collegue of mine, we passed by some rubbish bins outside an apartment complex. On the top of these bins there were lying a huge mirror. About 2meters 20cm by 40cm or something. There was, as far as what we could see nothing wrong with it at all, so we took it. I&#8217;ve wanted to buy a big mirror for a long time, but mirrors are very expensive. (Thats why it means seven years of bad luck if you break one or throw one away).</p>
<p>But, I cant help but wonder why people would throw away such an expensive piece of furniture.<br />
I guess the best explaination is that someone moved away from one of the apartments without taking the furniture with them, and then the landlord throw away their stuff.</p>
<p>PS: It is not our intention to steal it, so if someone claims it we will give it back.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.elzapp.com/2008/04/04/mirror.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>w00t?</title>
		<link>http://blog.elzapp.com/2008/03/25/w00t.html</link>
		<comments>http://blog.elzapp.com/2008/03/25/w00t.html#comments</comments>
		<pubDate>Tue, 25 Mar 2008 12:30:34 +0000</pubDate>
		<dc:creator>elzapp</dc:creator>
				<category><![CDATA[english]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sikkerhet]]></category>
		<category><![CDATA[undring]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://blog.elzapp.com/2008/03/25/w00t.html</guid>
		<description><![CDATA[Today I noticed this in my access.log: ?View Code APACHE67.19.113.154 - - [24/Mar/2008:16:02:10 +0100] &#34;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#34; 400 363 &#34;-&#34; &#34;-&#34; 65.111.181.35 - - [24/Mar/2008:20:02:22 +0100] &#34;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#34; 400 363 &#34;-&#34; &#34;-&#34; 67.19.113.154 - - [24/Mar/2008:20:15:38 +0100] &#34;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#34; 400 363 &#34;-&#34; &#34;-&#34; 67.19.113.154 - - [25/Mar/2008:00:26:37 +0100] &#34;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#34; 400 363 [...]]]></description>
			<content:encoded><![CDATA[<p>Today I noticed this in my access.log:</p>

<div class="wp_codebox_msgheader"><span class="right"><sup><a href="http://www.ericbess.com/ericblog/2008/03/03/wp-codebox/#examples" target="_blank" title="WP-CodeBox HowTo?"><span style="color: #99cc00">?</span></a></sup></span><span class="left"><a href="javascript:;" onclick="javascript:showCodeTxt('p294code2'); return false;">View Code</a> APACHE</span><div class="codebox_clear"></div></div><div class="wp_codebox"><table><tr id="p2942"><td class="code" id="p294code2"><pre class="apache" style="font-family:monospace;">67.19.113.154 - - [<span style="color: #ff0000;">24</span>/Mar/<span style="color: #ff0000;">2008</span>:<span style="color: #ff0000;">16</span>:02:<span style="color: #ff0000;">10</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
65.111.181.35 - - [<span style="color: #ff0000;">24</span>/Mar/<span style="color: #ff0000;">2008</span>:<span style="color: #ff0000;">20</span>:02:<span style="color: #ff0000;">22</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
67.19.113.154 - - [<span style="color: #ff0000;">24</span>/Mar/<span style="color: #ff0000;">2008</span>:<span style="color: #ff0000;">20</span>:<span style="color: #ff0000;">15</span>:<span style="color: #ff0000;">38</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
67.19.113.154 - - [<span style="color: #ff0000;">25</span>/Mar/<span style="color: #ff0000;">2008</span>:00:<span style="color: #ff0000;">26</span>:<span style="color: #ff0000;">37</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
67.19.113.154 - - [<span style="color: #ff0000;">25</span>/Mar/<span style="color: #ff0000;">2008</span>:04:<span style="color: #ff0000;">37</span>:<span style="color: #ff0000;">39</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
...
67.19.113.154 - - [<span style="color: #ff0000;">25</span>/Mar/<span style="color: #ff0000;">2008</span>:08:<span style="color: #ff0000;">52</span>:<span style="color: #ff0000;">25</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
67.19.113.154 - - [<span style="color: #ff0000;">25</span>/Mar/<span style="color: #ff0000;">2008</span>:<span style="color: #ff0000;">13</span>:05:07 +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span></pre></td></tr></table></div>

<p>What goes on here?<br />
All these requests fail, ofcourse, but in addition to the obvious (404), the client also doesnt supply a <code>Host: </code> header for their HTTP/1.1 requests</p>
<h4>update</h4>
<p>It is safe to assume that this is an attempt to hack me in some way, DFind is appearantly some kind of security scanner<a href="http://www.atlink.it/~conti/2006/03/04/w00tw00tatiscsansdfind-update/"><sup>ref</sup></a>. The same IPs are also bruteforcing some URLs (like /phpmyadmin etc..) looking for somthing fun to poke around with.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.elzapp.com/2008/03/25/w00t.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
